undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,47 @@
/*
* Copyright (c) 2001, 2012, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/* @test
* @bug 4442373
* @summary Verify that RMI can successfully unmarshal Class objects for
* primitive types. This test does not affect VM global state,
* so othervm is not required.
* @run main PrimitiveClasses
*/
import java.rmi.MarshalledObject;
public class PrimitiveClasses {
public static void main(String[] args) throws Exception {
Class[] primClasses = {
boolean.class, byte.class, char.class, short.class,
int.class, long.class, float.class, double.class
};
for (int i = 0; i < primClasses.length; i++) {
Class pc = primClasses[i];
if (new MarshalledObject(pc).get() != pc) {
throw new Error();
}
}
}
}

View file

@ -0,0 +1,39 @@
/*
* Copyright (c) 1999, 2012, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/**
*
*/
import java.rmi.Remote;
import java.rmi.RemoteException;
/*
* Interface with methods to exercise RMI parameter marshalling
* and unmarshalling.
*/
interface CheckUnmarshal extends java.rmi.Remote {
public PoisonPill getPoisonPill() throws RemoteException;
public Object ping() throws RemoteException;
public void passRuntimeExceptionParameter(
RuntimeExceptionParameter rep)
throws RemoteException;
}

View file

@ -0,0 +1,199 @@
/*
* Copyright (c) 1998, 2012, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/* @test
* @bug 4118600
* @summary RMI UnmarshallException, interaction on stopping a thread.
*
* @bug 4177704
* @summary RuntimeExceptions can corrupt call connections that may be reused.
*
* @author Laird Dornin
*
* @library ../../../testlibrary
* @modules java.rmi/sun.rmi.registry
* java.rmi/sun.rmi.server
* java.rmi/sun.rmi.transport
* java.rmi/sun.rmi.transport.tcp
* @build TestLibrary CheckUnmarshal CheckUnmarshalOnStopThread_Stub
* PoisonPill RuntimeExceptionParameter
* @run main/othervm/timeout=480 CheckUnmarshalOnStopThread
*/
import java.rmi.*;
import java.rmi.server.*;
import java.io.*;
import java.rmi.registry.*;
/**
* Description for 4118600:
*
* If an rmi call thread is stopped while unmarshalling a return
* value), java.lang.ThreadDeath will be thrown during
* UnicastRef.invoke(...). If rmi handles the Error properly, the
* remote method connection will not be reused. Otherwise the
* connection can be freed and reused in a corrupted state, which will
* lead to the throwing of an UnmarshalException the next time the
* connection is used.
*
* To test RMI Error handling, the test invokes the remote call,
* getPoisonPill, a number of times. This method returns an object
* which throws an Error on return value deserialization (from its
* readObject method). If RMI handles the error correctly, another
* remote call, ping, should execute correctly (i.e. with no
* exceptions). The test fails if the ping method throws an
* UnmarshalException.
*
* The old way that the test used to operate:
*
* Iterate a large number of times: each iteration spawns a thread
* that makes multiple rmi calls, sleep for 10 milliseconds, then stop
* the thread that is making the rmi calls (hopefully during return
* value Unmarshalling).
*
* Count the number of UnmarshalExceptions that occur during test
* iterations. If this number is > 10, then the test fails.
*
* Note: Even if rmi is catching java.lang.ThreadDeath properly, other
* types of exceptions (often related to monitor state, etc.) can
* occur. This test is only written to track UnmarshalExceptions;
* success/failure does not depend on other types of problems.
*
* Description for 4177704:
*
* Similar situation as for 4177704 except that instead of just
* ensuring that RMI properly handles Errors, the second part of the
* test ensures that RMI deals with RuntimeExceptions correctly.
*
* Test also ensures that call connections are freed without reuse
* when RuntimeExceptions are thrown during the marshalling of call
* parameters. An object that throws a RuntimeException in its
* writeObject method helps to carry out this part of the test.
*/
public class CheckUnmarshalOnStopThread
extends UnicastRemoteObject
implements CheckUnmarshal
{
final static int RUNTIME_PILL = 1;
public static int typeToThrow = 0;
/*
* remote object implementation
*/
CheckUnmarshalOnStopThread() throws RemoteException { }
public PoisonPill getPoisonPill() throws RemoteException {
return new PoisonPill(new Integer(0));
}
public Object ping() throws RemoteException {
return (Object) new Integer(0);
}
public void passRuntimeExceptionParameter(
RuntimeExceptionParameter rep) throws RemoteException
{
// will never be called
}
public static void main(String [] args) {
Object dummy = new Object();
CheckUnmarshal cu = null;
CheckUnmarshalOnStopThread cuonst = null;
System.err.println("\nregression test for bugs: " +
"4118600 and 4177704\n");
try {
cuonst = new CheckUnmarshalOnStopThread();
cu = (CheckUnmarshal) UnicastRemoteObject.toStub(cuonst);
// make sure that RMI will free connections appropriately
// under several situations:
// when Errors are thrown during parameter unmarshalling
System.err.println("testing to see if RMI will handle errors");
ensureConnectionsAreFreed(cu, true);
// when RuntimeExceptions are thrown during parameter unmarshalling
System.err.println("testing to see if RMI will handle " +
"runtime exceptions");
typeToThrow = RUNTIME_PILL;
ensureConnectionsAreFreed(cu, true);
// when RuntimeExceptions are thrown during parameter marshalling
System.err.println("testing to see if RMI will handle " +
"runtime exceptions thrown during " +
"parameter marshalling");
ensureConnectionsAreFreed(cu, false);
System.err.println
("\nsuccess: CheckUnmarshalOnStopThread test passed ");
} catch (Exception e) {
TestLibrary.bomb(e);
} finally {
cu = null;
deactivate(cuonst);
}
}
static void ensureConnectionsAreFreed(CheckUnmarshal cu, boolean getPill)
throws Exception
{
// invoke a remote call that will corrupt a call connection
// that will not be freed (if the bug is not fixed)
for (int i = 0 ; i < 250 ; i++) {
try {
Object test = cu.ping();
if (getPill) {
cu.getPoisonPill();
} else {
cu.passRuntimeExceptionParameter(
new RuntimeExceptionParameter());
}
} catch (Error e) {
// expect an Error from call unmarshalling, ignore it
} catch (RuntimeException e) {
// " RuntimeException "
}
}
System.err.println("remote calls passed, received no " +
"unmarshal exceptions\n\n");
}
static void deactivate(RemoteServer r) {
// make sure that the object goes away
try {
System.err.println("deactivating object.");
UnicastRemoteObject.unexportObject(r, true);
} catch (Exception e) {
e.getMessage();
e.printStackTrace();
}
}
}

View file

@ -0,0 +1,166 @@
/*
* Copyright (c) 1998, 2008, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
// Stub class generated by rmic, do not edit.
// Contents subject to change without notice.
public final class CheckUnmarshalOnStopThread_Stub
extends java.rmi.server.RemoteStub
implements CheckUnmarshal, java.rmi.Remote
{
private static final java.rmi.server.Operation[] operations = {
new java.rmi.server.Operation("PoisonPill getPoisonPill()"),
new java.rmi.server.Operation("void passRuntimeExceptionParameter(RuntimeExceptionParameter)"),
new java.rmi.server.Operation("java.lang.Object ping()")
};
private static final long interfaceHash = -5923540687975666490L;
private static final long serialVersionUID = 2;
private static boolean useNewInvoke;
private static java.lang.reflect.Method $method_getPoisonPill_0;
private static java.lang.reflect.Method $method_passRuntimeExceptionParameter_1;
private static java.lang.reflect.Method $method_ping_2;
static {
try {
java.rmi.server.RemoteRef.class.getMethod("invoke",
new java.lang.Class[] {
java.rmi.Remote.class,
java.lang.reflect.Method.class,
java.lang.Object[].class,
long.class
});
useNewInvoke = true;
$method_getPoisonPill_0 = CheckUnmarshal.class.getMethod("getPoisonPill", new java.lang.Class[] {});
$method_passRuntimeExceptionParameter_1 = CheckUnmarshal.class.getMethod("passRuntimeExceptionParameter", new java.lang.Class[] {RuntimeExceptionParameter.class});
$method_ping_2 = CheckUnmarshal.class.getMethod("ping", new java.lang.Class[] {});
} catch (java.lang.NoSuchMethodException e) {
useNewInvoke = false;
}
}
// constructors
public CheckUnmarshalOnStopThread_Stub() {
super();
}
public CheckUnmarshalOnStopThread_Stub(java.rmi.server.RemoteRef ref) {
super(ref);
}
// methods from remote interfaces
// implementation of getPoisonPill()
public PoisonPill getPoisonPill()
throws java.rmi.RemoteException
{
try {
if (useNewInvoke) {
Object $result = ref.invoke(this, $method_getPoisonPill_0, null, 5776441251039617360L);
return ((PoisonPill) $result);
} else {
java.rmi.server.RemoteCall call = ref.newCall((java.rmi.server.RemoteObject) this, operations, 0, interfaceHash);
ref.invoke(call);
PoisonPill $result;
try {
java.io.ObjectInput in = call.getInputStream();
$result = (PoisonPill) in.readObject();
} catch (java.io.IOException e) {
throw new java.rmi.UnmarshalException("error unmarshalling return", e);
} catch (java.lang.ClassNotFoundException e) {
throw new java.rmi.UnmarshalException("error unmarshalling return", e);
} finally {
ref.done(call);
}
return $result;
}
} catch (java.lang.RuntimeException e) {
throw e;
} catch (java.rmi.RemoteException e) {
throw e;
} catch (java.lang.Exception e) {
throw new java.rmi.UnexpectedException("undeclared checked exception", e);
}
}
// implementation of passRuntimeExceptionParameter(RuntimeExceptionParameter)
public void passRuntimeExceptionParameter(RuntimeExceptionParameter $param_RuntimeExceptionParameter_1)
throws java.rmi.RemoteException
{
try {
if (useNewInvoke) {
ref.invoke(this, $method_passRuntimeExceptionParameter_1, new java.lang.Object[] {$param_RuntimeExceptionParameter_1}, -4427599990679364365L);
} else {
java.rmi.server.RemoteCall call = ref.newCall((java.rmi.server.RemoteObject) this, operations, 1, interfaceHash);
try {
java.io.ObjectOutput out = call.getOutputStream();
out.writeObject($param_RuntimeExceptionParameter_1);
} catch (java.io.IOException e) {
throw new java.rmi.MarshalException("error marshalling arguments", e);
}
ref.invoke(call);
ref.done(call);
}
} catch (java.lang.RuntimeException e) {
throw e;
} catch (java.rmi.RemoteException e) {
throw e;
} catch (java.lang.Exception e) {
throw new java.rmi.UnexpectedException("undeclared checked exception", e);
}
}
// implementation of ping()
public java.lang.Object ping()
throws java.rmi.RemoteException
{
try {
if (useNewInvoke) {
Object $result = ref.invoke(this, $method_ping_2, null, 7635508643486276040L);
return ((java.lang.Object) $result);
} else {
java.rmi.server.RemoteCall call = ref.newCall((java.rmi.server.RemoteObject) this, operations, 2, interfaceHash);
ref.invoke(call);
java.lang.Object $result;
try {
java.io.ObjectInput in = call.getInputStream();
$result = (java.lang.Object) in.readObject();
} catch (java.io.IOException e) {
throw new java.rmi.UnmarshalException("error unmarshalling return", e);
} catch (java.lang.ClassNotFoundException e) {
throw new java.rmi.UnmarshalException("error unmarshalling return", e);
} finally {
ref.done(call);
}
return $result;
}
} catch (java.lang.RuntimeException e) {
throw e;
} catch (java.rmi.RemoteException e) {
throw e;
} catch (java.lang.Exception e) {
throw new java.rmi.UnexpectedException("undeclared checked exception", e);
}
}
}

View file

@ -0,0 +1,61 @@
/*
* Copyright (c) 1999, 2008, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/**
*
*/
import java.io.IOException;
import java.io.ObjectInputStream;
import java.io.Serializable;
/**
* Class whos readObject method throws a RuntimeException or an
* Error. Helps to make sure that the UnicastRef.invoke method
* handles ThreadDeath errors correctly (frees relevant corrupted
* call connections with out reuse).
*/
public class PoisonPill implements Serializable {
Integer corruptTheCallStream = null;
PoisonPill(Integer corruptTheCallStream) {
this.corruptTheCallStream = corruptTheCallStream;
}
private void readObject(ObjectInputStream in)
throws IOException
{
if (CheckUnmarshalOnStopThread.typeToThrow !=
CheckUnmarshalOnStopThread.RUNTIME_PILL) {
throw new Error("Wrote a test object whos readObject " +
"method always throws an Error");
} else {
throw new RuntimeException("Wrote a test object " +
"whos readObject method " +
"always throws a RuntimeException");
}
}
}

View file

@ -0,0 +1,43 @@
/*
* Copyright (c) 1999, 2008, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/**
*
*/
import java.io.IOException;
import java.io.ObjectOutputStream;
import java.io.Serializable;
/**
* Class to help verify that RMI handles RuntimeExceptions on parameter
* marshalling correctly.
*/
class RuntimeExceptionParameter implements Serializable {
private void writeObject(ObjectOutputStream out)
throws IOException
{
throw new RuntimeException("wrote a parameter whos writeObject " +
"method always throws a RuntimeException"
);
}
}